First published: Thu Apr 16 2020(Updated: )
A use-after-free issue exists in WebKitGTK before 2.28.1 and WPE WebKit before 2.28.1 via crafted web content that allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash).
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WebKitGTK WebKitGTK | <2.28.1 | |
Wpewebkit Wpe Webkit | <2.28.1 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =19.10 | |
Fedoraproject Fedora | =30 | |
Fedoraproject Fedora | =31 | |
Fedoraproject Fedora | =32 | |
openSUSE Leap | =15.1 | |
redhat/webkitgtk | <2.28.1 | 2.28.1 |
ubuntu/webkit2gtk | <2.28.1-0ubuntu0.18.04.1 | 2.28.1-0ubuntu0.18.04.1 |
ubuntu/webkit2gtk | <2.28.1-0ubuntu0.19.10.1 | 2.28.1-0ubuntu0.19.10.1 |
ubuntu/webkit2gtk | <2.28.1-1 | 2.28.1-1 |
ubuntu/webkit2gtk | <2.28.1-1 | 2.28.1-1 |
ubuntu/webkit2gtk | <2.28.1-1 | 2.28.1-1 |
ubuntu/webkit2gtk | <2.28.1-1 | 2.28.1-1 |
ubuntu/webkit2gtk | <2.28.1-1 | 2.28.1-1 |
ubuntu/webkit2gtk | <2.28.1-1 | 2.28.1-1 |
ubuntu/webkit2gtk | <2.28.1-1 | 2.28.1-1 |
ubuntu/webkit2gtk | <2.28.1-1 | 2.28.1-1 |
ubuntu/webkit2gtk | <2.28.1-1 | 2.28.1-1 |
ubuntu/webkit2gtk | <2.28.1 | 2.28.1 |
debian/webkit2gtk | 2.44.2-1~deb11u1 2.44.2-1~deb12u1 2.44.2-1 | |
debian/wpewebkit | 2.38.6-1~deb11u1 2.38.6-1 2.44.2-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-11793 is a use-after-free vulnerability in WebKitGTK and WPE WebKit that allows remote attackers to execute arbitrary code or cause a denial of service.
CVE-2020-11793 affects WebKitGTK before version 2.28.1 and WPE WebKit before version 2.28.1.
CVE-2020-11793 has a severity score of 8.8, which is considered high.
To fix CVE-2020-11793, you should update WebKitGTK to version 2.28.1 or later.
You can find more information about CVE-2020-11793 on the MITRE CVE website, the WebKitGTK security advisory, and the Ubuntu Security Notice.